Snort mailing list archives
Re[2]: unified format
From: Igor Belikov <ivb () is ua>
Date: Fri, 19 Aug 2005 13:29:07 +0300
Hello Roland, Friday, August 19, 2005, 12:36:45 PM, you wrote:
1. In archive of this mailing list I read that unified alert file contains only alerts information, and unified log file contains both alerts and corresponding payloads. But documentation says different: unified log contains only payload, and I confirmed this by some tests.
RTS> The unified log format does not contain broken out fields for RTS> protocol-number or src/dest ip-address/port-number, while the unified RTS> alert format does. This information is, however, still available in the RTS> payload in the unified log format. The gen:sid:rev, classification, RTS> priority, eventid and timestamps are presented identically in both formats RTS> as part of the Event struct. It's sounds good for me, but I can't correctly configure barnyard to extract all needing info from unified log. When I run barnyard to monitor unified log - no events stored in DB. Please, anybody can help me to configure barnyard? -- Best regards, Igor mailto:ivb () is ua ------------------------------------------------------- SF.Net email is Sponsored by the Better Software Conference & EXPO September 19-22, 2005 * San Francisco, CA * Development Lifecycle Practices Agile & Plan-Driven Development * Managing Projects & Teams * Testing & QA Security * Process Improvement & Measurement * http://www.sqe.com/bsce5sf _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- unified format Igor Belikov (Aug 18)
- <Possible follow-ups>
- Re: unified format Roland Turner (SourceForge) (Aug 19)
- Re[2]: unified format Igor Belikov (Aug 19)
- Re: Re[2]: unified format Roland Turner (SourceForge) (Aug 19)
- Re[4]: unified format Igor Belikov (Aug 19)
- Re: Re[4]: unified format Roland Turner (SourceForge) (Aug 19)
- Message not available
- Fwd: Re[4]: unified format Bamm Visscher (Aug 19)
- Re: Fwd: Re[4]: unified format Igor Belikov (Aug 22)
- Message not available